CVE-2019-25358
FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-character buffer to cause the application to crash when opening options.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.03%
- CWE
- CWE-1282
- Published
- 2026-02-18
- Last modified
- 2026-03-14
Affected products
- nikkhokkho FileOptimizer
Weakness type
Related vulnerabilities
- CVE-2018-25229 — BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
- CVE-2019-25590 — Axessh 4.2 Denial of Service via Log File Name
- CVE-2019-25588 — BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address
- CVE-2019-25587 — BulletProof FTP Server 2019.0.0.50 Storage-Path Denial of Service
- CVE-2019-25583 — RarmaRadio 2.72.3 Username Field Denial of Service
- CVE-2019-25551 — Sandboxie 5.30 Denial of Service via Program Alerts Buffer Overflow
- CVE-2022-2483